Legal

Privacy Policy

Draft — last updated 26 July 2026
Before this goes live

This is a good-faith starting draft, grounded in what Northlight actually collects today — it has not been reviewed by a lawyer. GDPR carries real enforcement risk (fines up to €20M or 4% of global turnover for serious breaches), and this should be reviewed by qualified counsel before real customer data flows through it at any meaningful scale.

Who we are

Northlight (currently operating as a Swedish Enskild Firma, transitioning to Northlight Software AB) is the data controller for personal data collected through this website. We're based in Sweden.

Contact: [email protected] — placeholder, needs a real, monitored address before launch.

What we collect, and why

We only collect what you give us directly through our waitlist and inquiry forms. We don't currently use cookies, analytics, or any tracking technology on this site.

DataWhy we collect itLegal basis
Name, emailTo respond to your inquiry or notify you when a product launchesLegitimate interest / consent
Company, phone (optional)To understand who we're talking to and follow up appropriatelyLegitimate interest
Your messageTo understand and respond to what you're askingLegitimate interest
Which page/campaign you came fromSo we know which outreach is actually working — not tied to your identity beyond thisLegitimate interest

Note on marketing consent: if you join a waitlist, we take that as consent to email you about that specific product's launch — nothing broader, and you can withdraw it any time.

How long we keep it

Default policy (placeholder, needs confirming): we retain inquiry and waitlist data for 24 months from your last contact with us, or until you ask us to delete it — whichever comes first. This hasn't been finalized as an actual company policy yet.

Where your data lives, and who sees it

Your data is stored on infrastructure hosted in the EU (France), and is not shared with, sold to, or processed by any third party. Northlight is a solo-operated company — the only person with access to this data is Northlight's owner.

Your rights under GDPR

You have the right to:

To exercise any of these, contact us at the email address above.

Cookies and future changes

This site currently uses no cookies or tracking of any kind. As we begin running ads (LinkedIn, Google) to reach potential customers, that will change, and this policy — along with a proper cookie-consent mechanism — will be updated before those go live, not after.

If you become a customer of our products

This policy covers your visit to this website — inquiries, waitlist signups, and similar. If you become a customer of a Northlight product (for example, the trucking compliance co-pilot), a separate agreement applies to the data you enter about your own drivers and vehicles. In that relationship, your company is the data controller and Northlight acts as a data processor on your behalf — a distinct legal relationship from the one this policy describes, governed by its own Data Processing Addendum presented at product signup, not by this page.

Changes to this policy

We'll update the "last updated" date above whenever this changes, and post material changes here directly.